A superuser account is any administrative account that grants full access to an operating system or application such as a database. On Linux and UNIX platforms, system accounts such as root or service accounts such as oracle are needed for installation, configuration, administration and management tasks. But as Gartner (Research Report ID# G00130427) has noted, Linux and UNIX systems inherently lack a scalable and simple model for administrative delegation. In many organizations Linux and UNIX personnel - such as system administrators, DBAs, backup operators and help desk staff - are routinely given increased privileges to accomplish even narrowly focused administrative tasks such as performing backups or managing a web site.
Organizations are becoming increasing aware of the risk that such broad administrative grants pose for potential theft of corporate IP, insider attacks, or even inadvertent changes that adversely affect systems or data. But alternatives such as sudo are frequently so complex to manage that some organizations simply live with the exposure because they have no practical way to limit privileges without hindering users in performing necessary administrative tasks.
The Centrify Suite provides a single, unified privilege management solution across more than 225 Linux and UNIX platforms. Instead of relying on complex scripting, proprietary databases, or expensive server architectures, Centrify joins your Linux and UNIX systems to your existing Active Directory infrastructure. You can then model Linux and UNIX user roles within Active Directory and apply those roles to the existing Active Directory identities. With the Centrify Suite you can:
... the capabilities in DirectControl give enterprises increased flexibility and security when administering their heterogeneous environments, increasing the business value of enterprise investments in both Active Directory and distributed systems.
Michael Dortch
Principal Business Analyst
Robert Frances Group